US2017063883A1PendingUtilityA1

Metadata information based file processing

Assignee: FORTINET INCPriority: Aug 26, 2015Filed: Aug 26, 2015Published: Mar 2, 2017
Est. expiryAug 26, 2035(~9.1 yrs left)· nominal 20-yr term from priority
H04L 63/1416H04L 63/102H04L 63/107H04L 63/0263
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods and systems for network level file processing based on metadata information retrieved from a file are provided. According to one embodiment, a file is received by a network security appliance. Metadata information is extracted from the file. The extracted metadata information is processed based on one or more defined rules. An action is taken on one or more of the file or a sender of the file based on an outcome of the processing.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system comprising:
 one or more processors; and   a memory containing therein:
 a file receive module configured to receive a file; 
 a metadata extraction module configured to extract metadata information relating to the file; 
 a metadata based policy implementation module configured to process extracted metadata information based on one or more defined rules; and 
 a metadata comparison based action module configured to take an action on the file and/or sender of the file based on an outcome of the processing. 
   
     
     
         2 . The system of  claim 1 , wherein the metadata information comprises one or a combination of descriptive attributes of the file, structural attributes of the file, administrative attributes of the file, title, creation details, modification details, an indication regarding a type of the file, format details, identifier details, language details, location details, actions taken on the file, purpose of the file, rights relating to the file, platform of the file, company to which the file belongs, and security parameters of the file. 
     
     
         3 . The system of  claim 1 , wherein the action comprises one or a combination of blocking the file, allowing the file, blocking the sender of the file, erasing all or a portion of the metadata information, modifying all or a portion of the metadata information, logging the file, classifying the file in a category, classifying the sender of the file in a class, generating a security alert, changing attributes of the file, and quarantining the file. 
     
     
         4 . The system of  claim 1 , wherein when the file is an image file and includes Exchangeable Image File Format (EXIF) information, at least one rule of the one or more defined rules processes the EXIF information to determine whether the EXIF information indicates the existence of malicious data. 
     
     
         5 . The system of  claim 1 , wherein Global Positioning System (GPS) coordinates of the file are determined and processed with at least one rule of the one or more defined rules, and wherein an action is taken on the file based on an outcome of the processing. 
     
     
         6 . The system of  claim 1 , wherein the metadata information to be extracted is configurable. 
     
     
         7 . The system of  claim 1 , wherein the metadata information is extracted based on any or a combination of a type of the file, a creator of the file, data stored in the file, a format of the file, a date of creation of the file, a date of modification of the file, a sender of the file, a desired purpose of processing the file, one or more configured security policies, and one or more configured information attributes. 
     
     
         8 . The system of  claim 1 , wherein the one or more defined rules are configurable and selectable. 
     
     
         9 . The system of  claim 1 , wherein content stored in the file is processed along with the extracted metadata information to determine the action. 
     
     
         10 . The system of  claim 1 , wherein the metadata information of the file is updated in real-time. 
     
     
         11 . A method comprising:
 receiving, by a network security appliance, a file;   extracting, by the network security appliance, metadata information from the file;   processing, by the network security appliance, the extracted metadata information based on one or more defined rules; and   taking an action, by the network security appliance, on one or more of the file or a sender of the file based on an outcome of the processing.   
     
     
         12 . The method of  claim 11 , wherein the extracted metadata information comprises one or a combination of descriptive attributes of the file, structural attributes of the file, administrative attributes of the file, title, creation details, modification details, an indication regarding a type of the file, format details, identifier details, language details, location details, actions taken on the file, purpose of the file, rights relating to the file, platform of the file, company to which the file belongs, and security parameters of the file. 
     
     
         13 . The method of  claim 11 , wherein the action comprises one or a combination of blocking the file, allowing the file, blocking the sender of the file, erasing all or a portion of the metadata information, modifying all or a portion of the metadata information, logging the file, classifying the file in a category, classifying the sender of the file in a class, generating a security alert, changing attributes of the file, and quarantining the file. 
     
     
         14 . The method of  claim 11 , wherein when a format of the file comprises Exchangeable Image file Format (EXIF), then at least one rule of the one or more defined rules processes the extracted metadata information to determine whether a known pattern of attack is present within the extracted metadata information. 
     
     
         15 . The method of  claim 11 , wherein the extracted metadata information includes global positioning system (GPS) coordinates that are processed with at least one rule of the one or more defined rules. 
     
     
         16 . The method of  claim 11 , wherein the metadata information to be extracted is configurable. 
     
     
         17 . The method of  claim 11 , wherein the metadata information is extracted based on any or a combination of a type of the file, a creator of the file, data stored in the file, a format of the file, a date of creation of the file, a date of modification of the file, a sender of the file, a desired purpose of processing the file, one or more configured security policies, and one or more configured information attributes. 
     
     
         18 . The method of  claim 11 , wherein the one or more defined rules are configurable and selectable. 
     
     
         19 . The method of  claim 11 , wherein content stored in the file is processed along with the extracted metadata information to determine the action. 
     
     
         20 . The method of  claim 11 , wherein metadata information of the file is updated in real-time.

Join the waitlist — get patent alerts

Track US2017063883A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.